CVE-2025-66238: Sunbird Dcim Dctrack

High severity, CVSS 7.2. EPSS: 0.3% chance of exploitation in the next 30 days.

DCIM dcTrack allows an attacker to misuse certain remote access features. An authenticated user with access to the appliance's virtual console could exploit these features to redirect network traffic, potentially accessing restricted services or data on the host machine.

Affected products

  • Sunbird Dcim Dctrack: up to and including v9.2.0
  • Sunbird Iq: up to and including v9.2.0

Published 2025-12-04. Last modified 2026-06-17.